Hipaa Compliance
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/retention-impact-assess .claude/skills/retention-impact-assess && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .claude/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/retention-impact-assess .agents/skills/retention-impact-assess && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .agents/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/retention-impact-assess .cursor/skills/retention-impact-assess && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .cursor/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/retention-impact-assess--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/retention-impact-assess .gemini/skills/retention-impact-assess && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .gemini/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/retention-impact-assess .github/skills/retention-impact-assess && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .github/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/retention-impact-assess .opencode/skills/retention-impact-assess && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "retention-impact-assess" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-impact-assess into .opencode/skills/retention-impact-assess/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-impact-assess", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
retention-impact-assessConducts retention impact assessments for new processing activities to determine appropriate data retention periods.
Retention Impact Assess is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Covers regulatory requirements scanning, proportionality review, purpose-based retention determination, and retention period documentation aligned with GDPR Article 5(1)(e) and Article 25 data protection by design. Activate for retention assessment, new processing retention, retention period determination queries.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR and Regulatory compliance. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Retention Impact Assess loads about 3.7k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 873 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 873 words, ~3,659 tokens.
.claude/skills/retention-impact-assess/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.A Retention Impact Assessment (RIA) is a structured evaluation conducted before commencing new processing activities (or significantly changing existing ones) to determine the appropriate retention period for personal data. The RIA ensures that retention periods are set proactively — by design — rather than retroactively after data has accumulated without defined limits. Under GDPR Article 25, data protection by design requires that storage limitation is considered at the design stage of any processing activity. This skill provides the assessment methodology, regulatory scanning framework, proportionality analysis, and documentation template for determining and justifying retention periods.
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
The controller shall implement appropriate technical and organisational measures designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing. This includes proactive determination of retention periods before processing begins.
Where a Data Protection Impact Assessment is required, it must include the envisaged processing operations and the purposes, including where applicable the legitimate interest pursued (Art. 35(7)(a)), and an assessment of the necessity and proportionality of the processing operations (Art. 35(7)(b)). Retention period determination is a core element of the necessity and proportionality assessment.
Data subjects must be informed of the period for which personal data will be stored, or the criteria used to determine that period. The RIA produces this information.
| Trigger | Description |
|---|---|
| New processing activity | Any new processing activity involving personal data that is not covered by an existing retention schedule entry |
| New system/application | Deployment of a new system, application, or database that will store personal data |
| Significant change to existing processing | Change in purpose, scope, data categories, or technology that materially affects the retention profile |
| New legal/regulatory requirement | New legislation or regulatory guidance that introduces or modifies retention requirements |
| Post-breach recommendation | Following a data breach where excessive retention was identified as a contributing factor |
| DPIA finding | Where a DPIA identifies retention period determination as an outstanding action |
| Vendor/processor change | Onboarding a new processor or service provider that will store personal data on behalf of the organization |
RETENTION IMPACT ASSESSMENT — Orion Data Vault Corp
-----------------------------------------------------
Assessment Reference: RIA-2026-0019
Date: 2026-03-14
Assessor: [Name, Title]
DPO Review: [Name]
SECTION 1: PROCESSING ACTIVITY
- Name of processing activity: [Description]
- Business owner: [Name, Department]
- Purpose(s) of processing: [List all purposes]
- Legal basis for processing: [Art. 6(1)(a)-(f)]
- Data subjects: [Categories — e.g., customers, employees, job applicants]
- Data categories: [List all personal data elements]
- Special category data: [Yes/No — if yes, specify Art. 9 condition]
- Estimated data volume: [Records per year / total expected volume]
- Data sources: [Collected directly from data subject / obtained from third party]
- Data recipients: [Internal departments, processors, third parties]
- International transfers: [Yes/No — if yes, specify destination countries]Systematically identify all legal and regulatory requirements that mandate minimum retention:
| Regulatory Domain | Applicable? | Statute/Regulation | Minimum Period | Notes |
|---|---|---|---|---|
| Tax and fiscal | □ | HMRC requirements; TMA 1970 | 6 years | Applies to financial transaction data |
| Company law | □ | Companies Act 2006 | 6 years | Applies to accounting records |
| Employment law | □ | Employment Rights Act 1996; Working Time Regulations 1998 | Varies (2-6 years) | Applies to employee data |
| Health and safety | □ | COSHH 2002; Ionising Radiations Regs 2017 | Up to 40 years | Applies to health monitoring records |
| Financial services | □ | MiFID II; FCA Handbook | 5-7 years | Applies to investment client records |
| AML/CTF | □ | MLR 2017; AMLD5 | 5 years | Applies to CDD and transaction monitoring |
| Sector-specific | □ | [Identify applicable sector regulations] | Varies | Varies |
| Contractual | □ | Contract terms with clients/partners | Per contract | Review contract clauses |
| Limitation periods | □ | Limitation Act 1980 | 3-12 years | Contract (6y), tort (3y), deed (12y) |
| Data protection | □ | GDPR; UK DPA 2018 | Storage limitation — no longer than necessary | Default principle |
| Jurisdiction | Applicable Law | Retention Requirement | Conflict with Primary? |
|---|---|---|---|
| UK | [Applicable UK statutes] | [Period] | N/A (primary jurisdiction) |
| EU Member State(s) | [Applicable EU/MS law] | [Period] | [Yes/No — resolve by applying longest] |
| US (if applicable) | [SOX, CCPA, state law] | [Period] | [Yes/No — resolve] |
| Other | [Specify] | [Period] | [Yes/No — resolve] |
For each processing purpose, determine the retention period independently:
PURPOSE-BASED RETENTION ANALYSIS
---------------------------------
Purpose 1: [Primary processing purpose]
- Legal basis: [Art. 6(1)(x)]
- Data categories needed: [List]
- Duration of purpose: [How long does this purpose persist?]
- Retention period for this purpose: [Duration]
- Justification: [Why this period is necessary and proportionate]
Purpose 2: [Secondary processing purpose — if any]
- Legal basis: [Art. 6(1)(x)]
- Data categories needed: [List — should be subset of or equal to Purpose 1]
- Duration of purpose: [How long does this purpose persist?]
- Retention period for this purpose: [Duration]
- Justification: [Why this period is necessary and proportionate]
Statutory Override (if applicable):
- Statute: [Citation]
- Mandatory minimum: [Period]
- This overrides Purpose [X] period: [Yes/No]
RESULTING RETENTION PERIOD: [The longest justified period across all purposes
and statutory requirements, but no longer than the maximum necessary period]The proportionality assessment ensures the retention period is no longer than necessary:
PROPORTIONALITY ASSESSMENT
----------------------------
1. NECESSITY
- Is the proposed retention period the minimum necessary to achieve
the stated purpose(s)? [Yes/No — justify]
- Could the purpose be achieved with a shorter retention period?
[Yes/No — justify]
- Could the purpose be achieved with anonymized or aggregated data
after a shorter period of identifiable retention? [Yes/No — justify]
2. DATA MINIMIZATION OVER TIME
- Can some data elements be deleted or anonymized before the full
retention period expires? [Yes/No — if yes, specify staged deletion]
- Example: Full data retained for 12 months for service delivery;
anonymized to aggregate statistics at 12 months; aggregates retained
for 3 years for trend analysis.
3. ACCESS RESTRICTION OVER TIME
- Should access be progressively restricted as the data ages?
- Example: Active access for first 12 months; restricted to compliance
team only for months 13-72; automated deletion at month 72.
4. RISK TO DATA SUBJECTS
- What is the risk to data subjects from the proposed retention?
[Low/Medium/High — justify]
- Does longer retention increase breach impact? [Yes/No]
- Are there specific data subject groups requiring heightened protection?
(e.g., children, vulnerable individuals)
5. ALTERNATIVES TO RETENTION
- Has anonymization been considered as an alternative? [Yes/No — outcome]
- Has pseudonymization been considered to reduce risk during retention?
[Yes/No — outcome]
- Has data aggregation been considered? [Yes/No — outcome]
PROPORTIONALITY CONCLUSION:
The proposed retention period of [X] is / is not proportionate because:
[Detailed justification — 2-3 paragraphs]RETENTION PERIOD RECOMMENDATION
---------------------------------
Data Category: [Description]
Processing Activity: [Name]
RECOMMENDED RETENTION STRUCTURE:
┌──────────────────────┬─────────────────────┬──────────────────────────────┐
│ Phase │ Duration │ Data State │
├──────────────────────┼─────────────────────┼──────────────────────────────┤
│ Active processing │ [Duration] │ Full data, full access │
│ Passive retention │ [Duration] │ Full data, restricted access │
│ Reduced retention │ [Duration] │ Minimized data, restricted │
│ Anonymized retention │ [Duration/indefinite]│ Anonymized, no restrictions │
│ Deletion │ At end of above │ Permanent deletion │
└──────────────────────┴─────────────────────┴──────────────────────────────┘
Total identifiable retention period: [Sum of active + passive + reduced]
Retention trigger: [Event that starts the retention clock]
Deletion method: [Automated / Manual / Anonymization]
JUSTIFICATION SUMMARY:
[Concise summary of legal basis, statutory requirements, purpose analysis,
and proportionality conclusion supporting this recommendation]
APPROVED BY:
- Business Owner: [Name] — Date: [YYYY-MM-DD]
- DPO: [Name] — Date: [YYYY-MM-DD]
- Legal (if statutory retention involved): [Name] — Date: [YYYY-MM-DD]After the RIA is approved, the following implementation steps must be completed:
| Step | Action | Responsible | Deadline |
|---|---|---|---|
| 1 | Add data category to retention schedule with approved period | DPO | Within 14 days of approval |
| 2 | Configure automated deletion rules in relevant systems | IT | Before processing commences |
| 3 | Update Records of Processing Activities (ROPA) with retention period | DPO | Within 14 days of approval |
| 4 | Update privacy notice to include retention period information | DPO / Marketing | Before processing commences |
| 5 | Configure access restrictions per phased retention structure | IT / Security | Before processing commences |
| 6 | Update service provider/processor agreements if applicable | Legal / Procurement | Before processing commences |
| 7 | Schedule first retention period review | DPO | Set for 12 months after processing starts |
| 8 | Brief data owners and relevant staff on retention requirements | DPO / Training | Before processing commences |
| Trigger | Action |
|---|---|
| Annual review date | Reassess all RIA assumptions — purpose still valid, regulatory landscape unchanged |
| Legislative change | Reassess statutory retention requirements |
| Processing change | Full RIA update if purpose, scope, or data categories change materially |
| Breach involving this data | Assess whether retention period contributed to breach scope; consider reduction |
| Data subject complaint | Review retention period proportionality in light of complaint |
| Technology change | Assess whether new technology enables shorter retention or better anonymization |
Orion Data Vault Corp maintains a register of all completed Retention Impact Assessments:
RIA REGISTER — Orion Data Vault Corp (Extract)
┌──────────────┬──────────────────────────┬────────────┬───────────────┬──────────────┬─────────────┐
│ RIA Ref │ Processing Activity │ Date │ Retention │ Status │ Next Review │
│ │ │ Completed │ Period │ │ │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2025-012 │ Customer loyalty program │ 2025-06-15 │ Membership + │ Active │ 2026-06-15 │
│ │ │ │ 2 years │ │ │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2025-018 │ Employee wellbeing survey │ 2025-09-01 │ 12 months │ Active │ 2026-09-01 │
│ │ │ │ (anonymize │ │ │
│ │ │ │ at 3 months) │ │ │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2026-019 │ Vendor loyalty programme │ 2026-03-14 │ 24 months │ In progress │ 2028-03-14 │
│ │ analytics │ │ (review at │ │ │
│ │ │ │ 12 months) │ │ │
└──────────────┴──────────────────────────┴────────────┴───────────────┴──────────────┴─────────────┘© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/retention-impact-assess of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Retention Impact Assess next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Retention Impact Assess this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Regulatory Audit Generatorzebbern/claude-code-guide | 4.7k | 1 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Reg Gap Analysisanthropics/claude-for-legal | 9.6k | 2 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Policy OpaAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Compliance Checkjosstei/maestro-orchestrate | 465 | — | ~237 | Automated safety check: Pass | Apache-2.0 |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
zebbern/claude-code-guide
Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.
anthropics/claude-for-legal
Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
josstei/maestro-orchestrate
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Retention Impact Assess is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.
Retention Impact Assess fits situations like: tasks that involve Privacy and GDPR; tasks that involve Regulatory compliance.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a claude-code`. Or copy the skill folder (skills/privacy/retention-impact-assess in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/retention-impact-assess in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a codex`. Or copy the skill folder (skills/privacy/retention-impact-assess in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/retention-impact-assess in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/retention-impact-assess, .gemini/skills/retention-impact-assess, .github/skills/retention-impact-assess and .opencode/skills/retention-impact-assess in your project.
Going by SKILL.md and its folder, Retention Impact Assess needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Retention Impact Assess is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Retention Impact Assess: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Regulatory Audit Generator (zebbern/claude-code-guide, 4.7k stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.